Applied research
Testing tomorrow's requirements today.
Our work is grounded in academic research. Prof. Dr. Aymen Gatri holds a professorship in IT Security at DBU Berlin, and our research feeds into how we assess emerging technologies — before the standards catch up.
Post-quantum cryptography
Cryptographic agility in constrained industrial devices. How do embedded systems with 10- to 20-year lifecycles migrate to post-quantum algorithms — and what does "harvest now, decrypt later" mean for products shipping today?
AI security & the AI Act
Security assessment of AI-enabled components: adversarial robustness, model integrity, and the intersection of the EU AI Act with existing product security requirements.
Supply chain integrity & SBOM
Machine-readable software bills of materials across multi-tier supply chains: what the CRA requires, what current tooling delivers, and where the gap between the two lies.
Nothing here yet
There is no entry to show at the moment.
Primary sources
Read it yourself.
We would rather you checked. These are the texts and the bodies behind everything claimed on this site.
The legislation
- Cyber Resilience ActOpens on an external siteThe full text, including Annex I requirements and the Article 14 reporting duty.Regulation (EU) 2024/2847
- NIS2 DirectiveOpens on an external siteRisk management and reporting duties for essential and important entities.Directive (EU) 2022/2555
- Radio Equipment Directive, Art. 3(3)Opens on an external siteThe delegated regulation that activated the network, privacy and fraud requirements.Delegated Reg. (EU) 2022/30
- Battery RegulationOpens on an external siteArticle 77 sets the first legally fixed Digital Product Passport deadline.Regulation (EU) 2023/1542
Standards & accreditation bodies
- ENISAOpens on an external siteThe EU agency that receives Article 14 reports and runs the single reporting platform.ENISA
- TUNACOpens on an external siteThe accreditation body that issued our ISO/IEC 17025 accreditation, 2-0155 — recognised internationally through the ILAC Mutual Recognition Arrangement. Verify it here.TUNAC
- ILAC signatory searchOpens on an external siteConfirm for yourself that a TUNAC report is recognised under the mutual recognition arrangement.ILAC MRA
- ETSIOpens on an external sitePublisher of EN 303 645, the consumer IoT baseline we assess against.ETSI
- BSIOpens on an external siteThe German federal cyber security authority behind Section 31 BSIG and the C5 catalogue.BSI